Recovery and resilience guide
A backup is not proven until someone restores it under realistic conditions.
Provider snapshots are useful, but recovery also requires independent copies, credentials, DNS knowledge and someone authorised to act.
Use the recovery standardPlan a safe migrationBackup creates a copy; recovery restores a functioning service. A pile of files nobody can use is digital archaeology, not resilience.
The recovery standard
| Control | Minimum expectation |
|---|---|
| Coverage | Files, database, media, configuration, DNS export and essential credentials. |
| Independence | At least one current copy outside the production hosting account. |
| Retention | Multiple recovery points covering accidental deletion and delayed discovery. |
| Integrity | Failures are detected and surfaced to an accountable owner. |
| Restoration | A scheduled test restores the service to a separate environment. |
| Access | Recovery credentials, MFA and keys have documented emergency access. |
Set recovery objectives
Recovery point
How much recent data can the business afford to lose?
Recovery time
How long can the service remain unavailable?
Recovery owner
Name the person who decides, communicates and verifies restoration.
Restore-test checklist
- Restore to a separate environment.
- Verify database, media, configuration and secrets.
- Test login, forms, checkout, redirects and transactional email.
- Confirm HTTPS, canonical URLs and robots settings.
- Record duration, failures and missing credentials.
- Update the runbook after every test.
Continue the decision
Last reviewed 17 July 2026.